Skip to main content

List of all Roles

The following are all the roles currently supported by Strata Cloud Manager:

RoleUI LabelDescription
adem_tier_1_supportADEM Tier 1 SupportFor use with the Prisma Access app. Read-only access to specific incident remediation workflows for only Prisma Access Autonomous Digital Experience Management (ADEM). No access to other Prisma Access services. No access to dashboards and Strata Logging Service (SLS) logs. Assign this role to third party helpdesk employees, tier 2 and 3 support, or administrators who only need ADEM access.
auditorAuditorRead-only access to functions related to all configurations, including subscriptions and licenses for the selected app. Includes access to view dashboards but cannot download, share, and schedule reports. Includes access to Strata Logging Service (SLS) logs. Assign this role to administrators who are tasked with examining the system for accuracy.
business_adminBusiness AdministratorRead and write access to all subscription and license management for the selected app. Includes read-only access to other functions, such as access policies, service accounts, and tenant service group operations. No access to dashboards and Strata Logging Service (SLS) logs. Includes the ability to activate product licenses through email activation link. Assign this role to administrators who manage devices, licenses, and subscriptions.
data_security_adminData Security AdministratorRead and write access to all data security functions for the selected app. Includes access to Strata Logging Service (SLS) logs, dashboards, create custom dashboards, and download, share, and schedule reports. Includes read-only access to logs. This role includes a very small subset of privileges included in the Security Admin role. Assign this role to administrators who manage only decryption rule configurations.
deployment_adminDeployment AdministratorThis role provides access to functions related to deployments. In addition, this role provides read-only access to other functions.
dlp_incident_adminDLP Incident AdministratorThis role provides access to functions related to dlp incident and report. This role also provides read-only access to other functions, including but not limited to: data profile, data filtering profile, data pattern, EDM and OCR settings.
dlp_policy_adminDLP Policy AdministratorThis role provides access to functions related to dlp policy including but not limited to: data profile, data filtering profile, data pattern, EDM and OCR settings.
iam_adminIAM AdministratorRead and write access to identity and authentication functions for the selected app. Includes read-only access to logs. No access to dashboards and Strata Logging Service (SLS) logs. Assign this role to administrators who manage users.
msp_iam_adminMultitenant IAM AdministratorRead and write access to identity and authentication functions for all tenants in a multitenant hierarchy. Restricted to read-only access for logs. No access to dashboards and Strata Logging Service (SLS) logs.
msp_superuserMultitenant SuperuserRead and write access to manage all apps, Strata Logging Service (SLS) logs, and services within the assigned level of nested hierarchy. Includes all permissions assigned to all roles, including Superuser. Includes access to dashboards, create custom dashboards, and download, share, and schedule reports. Includes the ability to activate product licenses through email activation link. Assign this role only to users or service accounts that require unrestricted access
mt_manage_userMultitenant Manage UserThis role provides access to functions related to multitenant management and other common resources.
mt_monitor_userMultitenant Monitor UserThis role provides access to functions related to multitenant monitoring and other common resources.
network_adminNetwork AdministratorRead and write access to logs and network policy configurations for the selected app. Includes read-only access to other functions: alerts, license quotas, devices, and tenant service group operations. Includes access to dashboards, create custom dashboards, and download, share, and schedule reports. Assign this role to administrators who need to maintain authentication, certificates, and decryption rules.
project_adminProject AdminThis role provides access to functions related to Dynamic Privilege Access
project_admin_pushProject Admin PushThis role provides access to push operations
seb_access_and_data_adminPA Browser Access & Data AdministratorPrisma Access Browser (PAB) data & access administrator role provides read & write access to set and manage access & data policies, defining custom/private applications, handling end user requests related to policies and read-only permission to inventory aspects (users, devices, extensions) and to any visibility aspects (dashboards, enduser events) within the Prisma Access Browser management sections
seb_customization_adminPA Browser Customization AdministratorPrisma Access Browser (PAB) customization administrator role provides read & write access to set and manage browser customization policies, and read-only permission to inventory aspects (users, devices, applications, extensions) and to any visibility aspects (dashboards, enduser events) within the Prisma Access Browser management sections.
seb_permission_request_adminPA Browser Permission Request AdministratorPrisma Access Browser (PAB) permission request administrator role provides read & write access to handle end user requests related to policies and read-only permission to visibility aspects (dashboards, end user events) within the Prisma Access Browser management sections.
seb_security_adminPA Browser Security AdministratorPrisma Access Browser (PAB) security administrator role provides read & write access to set and manage browser security policies, and read-only permission to inventory aspects (users, devices, applications, extensions) and to any visibility aspects (dashboards, enduser events) within the Prisma Access Browser management sections.
seb_security_and_posture_adminPA Browser Security & Device Posture AdministratorPrisma Access Browser (PAB) security & posture administrator role provides read & write access to set and manage browser security policies, manage device posture groups and set sign-in rules. It also provides read-only permission to inventory aspects (users, applications, extensions) and to any visibility aspects (dashboards, enduser events) within the Prisma Access Browser management sections.
seb_view_only_analytics_adminPA Browser View Only AnalyticsPrisma Access Browser (PAB) view only analytics role provides read access to any visibility aspects within the Prisma Access Browser management sections, including dashboards, detailed end user events and inventory aspects (users, devices, applications and extensions).
security_adminSecurity AdministratorThis role provides access to functions related to security policy configuration. This role also provides read-only access to other functions, including but not limited to: alerts, license quotas, devices, and tenant service group operations.
soc_adminSaaS SOC AdministratorThis role allows the administrator to assess incidents and remediate risks in SaaS Security. This administrator cannot access SaaS Security API settings or modify policy rules.
soc_analystSOC AnalystThis role provides read-only access to functions related to logs, reports, events, alerts, and all configuration. Assign this role to users or service accounts that need to view and investigate threats and trends.
sspm_appowner_superuserSaaS Posture Security AdministratorThis role provides full SSPM functionality but only for the SaaS application(s) that the administrator onboards themselves. It is intended to give IT/SaaS administrators full SSPM read and write access to the SaaS apps they are responsible for.
superuserSuperuserRead and write access to all available system-wide functions for the selected app. Includes all permissions assigned to all other roles, including MSP Superuser. Includes the ability to activate product licenses through email activation link. Assign this role only to users or service accounts that require unrestricted access.
tier_1_supportTier 1 SupportRead and write access to remediation workflows that update network, security, and device configurations for the selected app. Includes read-only access for alerts, access policies, configurations, license quotas, devices, and tenant service group operations. Full access to view dashboards, create custom dashboards, download, share, and schedule reports, and Strata Logging Service (SLS) logs.
tier_2_supportTier 2 SupportRead and write access to remediation workflows that update network, security, and device configurations for the selected app. Includes read-only access for alerts, access policies, configurations, license quotas, devices, and tenant service group operations. Full access to view dashboards, create custom dashboards, download, share, and schedule reports, and Strata Logging Service (SLS) logs.
view_only_adminView Only AdministratorRead-only access to all available system-wide functions for the selected app and logs. Includes access to view dashboards, download, share, and schedule reports.
web_security_adminWeb Security AdminThis role provides access to functions related to web security.